{"id":867,"date":"2026-07-13T20:46:48","date_gmt":"2026-07-13T20:46:48","guid":{"rendered":"https:\/\/blog.asambe.ai\/index.php\/2026\/07\/13\/90-minute-tabletop-exercise-with-a-dr-template\/"},"modified":"2026-07-13T20:46:49","modified_gmt":"2026-07-13T20:46:49","slug":"90-minute-tabletop-exercise-with-a-dr-template","status":"publish","type":"post","link":"https:\/\/blog.asambe.ai\/index.php\/2026\/07\/13\/90-minute-tabletop-exercise-with-a-dr-template\/","title":{"rendered":"90-Minute Tabletop Exercise with a DR Template"},"content":{"rendered":"<p>Outages don\u2019t schedule themselves. When systems fail or data goes missing, the fastest path to resilience is practice\u2014short, focused, repeatable practice. In 90 minutes, you can run a tabletop exercise that exposes weak spots, clarifies roles, and strengthens your disaster recovery plan without pulling everyone away for a full day.<\/p>\n<p>This guide shows you how to run a streamlined tabletop exercise using a simple disaster recovery (DR) template. You\u2019ll get a minute\u2011by\u2011minute agenda, a ready-to-copy template structure, role assignments, scenario ideas, and a checklist to capture real improvements\u2014not just discussion.<\/p>\n<h2>Table of Contents<\/h2>\n<ul>\n<li><a href=\"#what-is-a-tabletop-exercise\">What Is a Tabletop Exercise?<\/a><\/li>\n<li><a href=\"#why-90-minutes\">Why 90 Minutes Works<\/a><\/li>\n<li><a href=\"#90-minute-agenda\">The 90-Minute Agenda<\/a><\/li>\n<li><a href=\"#prepare-the-dr-template\">Prepare the Simple DR Template<\/a><\/li>\n<li><a href=\"#roles-and-participants\">Roles and Participants<\/a><\/li>\n<li><a href=\"#run-the-exercise-step-by-step\">Run the Exercise: Step by Step<\/a><\/li>\n<li><a href=\"#scenario-ideas-and-injects\">Scenario Ideas and Injects<\/a><\/li>\n<li><a href=\"#capture-outcomes-and-metrics\">Capture Outcomes and Metrics<\/a><\/li>\n<li><a href=\"#after-action-and-follow-up\">After-Action and Follow-Up<\/a><\/li>\n<li><a href=\"#common-pitfalls\">Common Pitfalls to Avoid<\/a><\/li>\n<li><a href=\"#tools-and-resources\">Tools and Resources<\/a><\/li>\n<li><a href=\"#conclusion-takeaways\">Conclusion and Takeaways<\/a><\/li>\n<li><a href=\"#frequently-asked-questions\">Frequently Asked Questions<\/a><\/li>\n<\/ul>\n<h2 id=\"what-is-a-tabletop-exercise\">What Is a Tabletop Exercise?<\/h2>\n<p>A tabletop exercise is a guided, discussion-based rehearsal of your response to a disruption\u2014no servers to rebuild, no real customer impact. Participants walk through a realistic scenario, make decisions, and map actions as if the event were live.<\/p>\n<p>Unlike full-scale simulations, tabletops are low cost, fast to schedule, and safe. They\u2019re ideal for validating your disaster recovery plan, clarifying communication paths, and revealing process, tooling, or documentation gaps before a real incident strikes.<\/p>\n<h2 id=\"why-90-minutes\">Why 90 Minutes Works<\/h2>\n<p>Ninety minutes is long enough to pressure-test your plan but short enough to fit into busy calendars. The timebox keeps discussion focused on impact, decisions, and next steps\u2014not rabbit holes.<\/p>\n<p>Short, frequent tabletops build muscle memory. You can run one per quarter across different scenarios or teams, compare outcomes over time, and continuously improve without fatigue or budget bloat.<\/p>\n<h2 id=\"90-minute-agenda\">The 90-Minute Agenda<\/h2>\n<p>Use this structure to stay on track. Display the agenda visibly so everyone can see the timeboxes.<\/p>\n<ol>\n<li><strong>Welcome and goals (0\u20135 min):<\/strong> State objectives, ground rules, and what \u201csuccess\u201d looks like today.<\/li>\n<li><strong>Scenario brief (5\u201310 min):<\/strong> Present the initial event, known facts, and constraints.<\/li>\n<li><strong>Roles and resources (10\u201320 min):<\/strong> Confirm roles, escalation paths, RTO\/RPO targets, and available playbooks.<\/li>\n<li><strong>Walkthrough with injects (20\u201360 min):<\/strong> Advance the scenario in stages; capture decisions, uncertainties, and actions.<\/li>\n<li><strong>Debrief and findings (60\u201380 min):<\/strong> Discuss what worked, what didn\u2019t, and immediate improvements.<\/li>\n<li><strong>Action owners and close (80\u201390 min):<\/strong> Assign owners, deadlines, and next steps. Confirm documentation updates.<\/li>\n<\/ol>\n<h2 id=\"prepare-the-dr-template\">Prepare the Simple DR Template<\/h2>\n<p>Before the session, share a one-page DR template that keeps everyone aligned. Keep it simple and easy to fill in as you go.<\/p>\n<h3>Template Sections (copy\/paste ready)<\/h3>\n<ul>\n<li><strong>System\/Service:<\/strong> What\u2019s impacted (name, owner, dependencies).<\/li>\n<li><strong>Business Impact:<\/strong> Critical functions, customers affected, compliance concerns.<\/li>\n<li><strong>RTO\/RPO Targets:<\/strong> Recovery Time Objective and Recovery Point Objective.<\/li>\n<li><strong>Detection &amp; Alerts:<\/strong> How the issue is detected; monitoring dashboards, logs, paging.<\/li>\n<li><strong>Decision Log:<\/strong> Timestamped choices, rationale, and approvers.<\/li>\n<li><strong>Communication Plan:<\/strong> Internal channels, status cadence, stakeholder list, customer messaging.<\/li>\n<li><strong>Recovery Steps:<\/strong> Ordered actions, tooling, scripts, runbooks, validation checks.<\/li>\n<li><strong>Escalation:<\/strong> Criteria, contacts, and on-call rotations.<\/li>\n<li><strong>Risks &amp; Assumptions:<\/strong> Known gaps, constraints, and dependencies.<\/li>\n<li><strong>Outcomes &amp; Metrics:<\/strong> Actual vs. target RTO\/RPO, decisions made, issues found, follow-ups.<\/li>\n<\/ul>\n<p>Print it or keep it live in a shared doc. The facilitator or scribe should update it in real time during the exercise.<\/p>\n<h2 id=\"roles-and-participants\">Roles and Participants<\/h2>\n<p>Assign clear roles to avoid cross-talk and ensure decisions are captured.<\/p>\n<ul>\n<li><strong>Sponsor:<\/strong> Sets objectives and ensures participation. Approves remediation resources.<\/li>\n<li><strong>Facilitator:<\/strong> Guides the exercise, controls pace, introduces injects, and enforces ground rules.<\/li>\n<li><strong>Scribe:<\/strong> Captures decisions, owners, timestamps, and metrics in the DR template.<\/li>\n<li><strong>Timekeeper:<\/strong> Keeps the team on schedule and signals section transitions.<\/li>\n<li><strong>Players:<\/strong> Representatives from operations, engineering, security, product, support, legal\/compliance, and communications.<\/li>\n<li><strong>Observers:<\/strong> Learn silently; may contribute in debriefs if time allows.<\/li>\n<\/ul>\n<h3>Ground Rules<\/h3>\n<ul>\n<li>Assume the scenario is real. Make decisions with current tools and information.<\/li>\n<li>Favor action over perfection. Document gaps you discover.<\/li>\n<li>One voice at a time. Keep comments to 60\u201390 seconds.<\/li>\n<li>Disagree respectfully; capture risks and move on.<\/li>\n<\/ul>\n<h2 id=\"run-the-exercise-step-by-step\">Run the Exercise: Step by Step<\/h2>\n<h3>1) Welcome and Goals<\/h3>\n<p>Share 2\u20133 objectives such as \u201cvalidate RTO for payments API,\u201d \u201cstress-test cross-team comms,\u201d or \u201cconfirm backup restoration steps.\u201d Outline success criteria: decisions logged, gaps identified, owners assigned.<\/p>\n<h3>2) Scenario Brief<\/h3>\n<p>Deliver a concise brief: what\u2019s happening, when it started, what\u2019s known\/unknown, and initial business impact. Keep it to one minute and display the facts on screen.<\/p>\n<h3>3) Roles and Resources<\/h3>\n<p>Confirm who\u2019s leading technical triage, communications, legal, and customer updates. Reiterate RTO\/RPO targets and surface available runbooks, dashboards, and escalation contacts. Note anything missing.<\/p>\n<h3>4) Walkthrough with Injects<\/h3>\n<ul>\n<li><strong>Stage 1:<\/strong> Initial detection and triage. What alerts fired? Who\u2019s paged? What\u2019s the first safe action?<\/li>\n<li><strong>Stage 2:<\/strong> Scope and containment. What systems are affected? Any blast-radius controls?<\/li>\n<li><strong>Stage 3:<\/strong> Recovery decision. Restore from backup? Fail over? Throttle traffic? Communicate externally?<\/li>\n<li><strong>Stage 4:<\/strong> Validation and return to service. How do you verify data integrity and business function?<\/li>\n<\/ul>\n<p>At each stage, introduce an inject (a new piece of information or constraint) to force decisions. Time-box discussion and move forward after decisions are recorded.<\/p>\n<h3>5) Debrief and Findings<\/h3>\n<p>Ask: What worked? What slowed us down? What decisions were risky or unclear? Which documents or tools helped? Capture each finding with a proposed improvement.<\/p>\n<h3>6) Action Owners and Close<\/h3>\n<p>Assign each action to an owner with a due date. Confirm where updates will live (runbooks, wikis, incident playbooks), when they will be reviewed, and who signs off.<\/p>\n<h2 id=\"scenario-ideas-and-injects\">Scenario Ideas and Injects<\/h2>\n<p>Pick a scenario that matches your biggest risks. Keep the technical details realistic but not overwhelming.<\/p>\n<h3>Popular Scenarios<\/h3>\n<ul>\n<li><strong>Ransomware in a file share:<\/strong> Encrypted files detected; backups exist but last successful snapshot is 12 hours old.<\/li>\n<li><strong>Cloud region outage:<\/strong> Primary region down; multi-region failover partially configured.<\/li>\n<li><strong>Database corruption:<\/strong> Data anomalies appear; point-in-time recovery available with 30-minute RPO.<\/li>\n<li><strong>Third-party SaaS degradation:<\/strong> Critical vendor API latency spikes; SLAs breached.<\/li>\n<li><strong>Insider error:<\/strong> Misconfigured access policy exposes data; audit trails incomplete.<\/li>\n<li><strong>Extreme weather event:<\/strong> Facility power interruptions; generator capacity limited.<\/li>\n<\/ul>\n<h3>Sample Injects<\/h3>\n<ul>\n<li>10 min: \u201cBackups restored successfully in staging, checksum mismatch in prod.\u201d<\/li>\n<li>20 min: \u201cSecurity requests delay to review suspicious login events before restore.\u201d<\/li>\n<li>30 min: \u201cCustomer escalations rise; social mentions increase 300%.\u201d<\/li>\n<li>45 min: \u201cFailover runbook step 7 references a deprecated tool.\u201d<\/li>\n<li>55 min: \u201cLegal requests holding statement approval before posting status page update.\u201d<\/li>\n<\/ul>\n<h2 id=\"capture-outcomes-and-metrics\">Capture Outcomes and Metrics<\/h2>\n<p>Measurable outcomes transform a discussion into progress. Track both process quality and technical readiness.<\/p>\n<h3>Core Metrics<\/h3>\n<ul>\n<li><strong>Decision latency:<\/strong> Time from detection to key decisions (containment, restore, failover, comms).<\/li>\n<li><strong>Escalation time:<\/strong> Minutes to engage the right SMEs or leadership.<\/li>\n<li><strong>Comms cadence:<\/strong> Frequency and clarity of internal and customer updates.<\/li>\n<li><strong>Runbook accuracy:<\/strong> Number of missing\/outdated steps discovered.<\/li>\n<li><strong>RTO\/RPO confidence:<\/strong> Evidence that targets are realistic given tools and process.<\/li>\n<li><strong>Single points of failure:<\/strong> Roles, tools, or knowledge concentrated in one person\/team.<\/li>\n<\/ul>\n<h3>Decision Log Tips<\/h3>\n<ul>\n<li>Time-stamp every decision with who decided and why.<\/li>\n<li>Record the options rejected and the risks accepted.<\/li>\n<li>Note data sources used (dashboards, logs, vendor status pages).<\/li>\n<\/ul>\n<h2 id=\"after-action-and-follow-up\">After-Action and Follow-Up<\/h2>\n<p>The value of a tabletop depends on what you fix afterward. Convert findings into a short After-Action Report (AAR) and track remediation to completion.<\/p>\n<h3>Fast AAR Structure<\/h3>\n<ul>\n<li><strong>Summary:<\/strong> Scenario, objectives, attendees, date.<\/li>\n<li><strong>What went well:<\/strong> Strengths to preserve.<\/li>\n<li><strong>What to improve:<\/strong> Top gaps and their impact.<\/li>\n<li><strong>Action plan:<\/strong> Owner, due date, success criteria for each item.<\/li>\n<li><strong>Policy\/process updates:<\/strong> What needs changing and where it will live.<\/li>\n<li><strong>Next exercise:<\/strong> Proposed scenario and date to validate improvements.<\/li>\n<\/ul>\n<p>Share the AAR within 48 hours. Add actions to your team\u2019s backlog with priority tags. Re-test the highest-risk fixes in the next 90-minute session.<\/p>\n<h2 id=\"common-pitfalls\">Common Pitfalls to Avoid<\/h2>\n<ul>\n<li><strong>Overcomplicated scenarios:<\/strong> Too many moving parts kill momentum. Keep it focused.<\/li>\n<li><strong>No clear objectives:<\/strong> If success isn\u2019t defined, you won\u2019t know when you\u2019ve achieved it.<\/li>\n<li><strong>Skipping the timebox:<\/strong> Endless debate helps no one. Decide, document, move on.<\/li>\n<li><strong>Tool talk rabbit holes:<\/strong> Capture tool gaps; don\u2019t demo features mid-exercise.<\/li>\n<li><strong>Unowned actions:<\/strong> Every finding needs an owner and date, or it will vanish.<\/li>\n<li><strong>Ignoring communications:<\/strong> Technical recovery without customer comms is half a plan.<\/li>\n<li><strong>No follow-up:<\/strong> Without an AAR and remediation tracking, you just had a meeting.<\/li>\n<\/ul>\n<h2 id=\"tools-and-resources\">Tools and Resources<\/h2>\n<h3>Simple Toolkit<\/h3>\n<ul>\n<li><strong>Shared document:<\/strong> Your DR template and live notes (e.g., Google Docs).<\/li>\n<li><strong>Timer:<\/strong> Visible countdown to enforce the agenda.<\/li>\n<li><strong>Virtual whiteboard:<\/strong> For dependency maps and timelines (e.g., Miro).<\/li>\n<li><strong>Communication channels:<\/strong> Chat room for the exercise, plus a mock status update flow.<\/li>\n<li><strong>Runbook repository:<\/strong> Central wiki or code repo with versioned procedures.<\/li>\n<li><strong>Incident comms scripts:<\/strong> Drafts for internal updates and customer notices.<\/li>\n<\/ul>\n<h3>Pre-Exercise Checklist<\/h3>\n<ul>\n<li>Send calendar invite with objectives and the DR template link.<\/li>\n<li>Confirm facilitator, scribe, and timekeeper.<\/li>\n<li>Select a scenario and 3\u20135 injects with timestamps.<\/li>\n<li>Prepare RTO\/RPO targets and relevant runbook links.<\/li>\n<li>Set up a shared doc and timer; test screen sharing.<\/li>\n<\/ul>\n<h3>During-Exercise Checklist<\/h3>\n<ul>\n<li>Start on time; review ground rules.<\/li>\n<li>Display the scenario brief and agenda.<\/li>\n<li>Advance injects on schedule; record decisions and owners.<\/li>\n<li>Keep discussions outcome-focused; capture tangents for later.<\/li>\n<\/ul>\n<h3>Post-Exercise Checklist<\/h3>\n<ul>\n<li>Publish AAR within 48 hours.<\/li>\n<li>Create tickets for each action with owners and due dates.<\/li>\n<li>Update runbooks, escalation lists, and comms templates.<\/li>\n<li>Schedule the next 90-minute tabletop to validate fixes.<\/li>\n<\/ul>\n<h2 id=\"conclusion-takeaways\">Conclusion and Takeaways<\/h2>\n<p>A well-run 90-minute tabletop turns theory into practical readiness. With a simple disaster recovery template, clear roles, and a tight agenda, you\u2019ll uncover gaps, align your team, and create an actionable plan to shorten recovery times and reduce risk.<\/p>\n<p>Start small, iterate often, and measure what matters. Your next outage won\u2019t wait\u2014neither should your practice.<\/p>\n<h2 id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n<p><strong>How often should we run tabletop exercises?<\/strong><\/p>\n<p>Quarterly is a good baseline. Rotate scenarios and teams so each critical system and function gets tested at least once per year.<\/p>\n<p><strong>Who needs to attend a 90-minute tabletop?<\/strong><\/p>\n<p>Include a facilitator, scribe, timekeeper, and decision-makers from operations, engineering, security, support, and communications. Invite legal\/compliance for regulated environments.<\/p>\n<p><strong>What artifacts should we produce?<\/strong><\/p>\n<p>A completed DR template, decision log, and a short After-Action Report with owners, due dates, and updates to runbooks and communication templates.<\/p>\n<p><strong>Can we combine disaster recovery and incident response?<\/strong><\/p>\n<p>Yes. Many scenarios touch both. Just define your objectives up front\u2014e.g., focus 60% on technical recovery steps and 40% on communications and escalation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how to run a 90-minute tabletop exercise using a simple disaster recovery template. Step-by-step agenda, roles, scenarios, and checklists for results.<\/p>\n","protected":false},"author":1,"featured_media":866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[8],"tags":[],"class_list":["post-867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blog.asambe.ai\/wp-content\/uploads\/2026\/07\/2026-07-13-20-46-36-data.png?fit=1024%2C1024&ssl=1","_links":{"self":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/comments?post=867"}],"version-history":[{"count":1,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/867\/revisions"}],"predecessor-version":[{"id":868,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/867\/revisions\/868"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media\/866"}],"wp:attachment":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media?parent=867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/categories?post=867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/tags?post=867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}